Search

Found 20,922 results in 749ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-27915 unknown 1.5 KEV 8mo ago Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user…
CVE-2025-52472 unknown 8mo ago XWiki Platform is vulnerable to HQL injection via wiki and space search REST API
CVE-2025-49594 unknown 8mo ago XWiki OIDC Authenticator: Users with "view" access can create tokens for any users they can view
CVE-2025-61882 unknown 2.5 KEVEXP 8mo ago Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise O…
CVE-2021-43226 unknown 1.5 KEV 8mo ago Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.
CVE-2013-3918 unknown 2.5 KEVEXP 8mo ago Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a sp…
CVE-2011-3402 unknown 2.5 KEVEXP 8mo ago Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via …
CVE-2010-3962 unknown 2.5 KEVEXP 8mo ago Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service…
CVE-2010-3765 unknown 2.5 KEVEXP 8mo ago Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameCo…
CVE-2025-43825 unknown 8mo ago Liferay Portal exposes sensitive user data through its Freemarker template
CVE-2025-54286 unknown FIX debian debian 8mo ago Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions…
CVE-2025-54287 unknown FIX debian debian 8mo ago Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the host system via special…
CVE-2025-54288 unknown FIX debian debian 8mo ago Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges within any container to impersonate other containers a…
CVE-2025-54289 unknown FIX debian debian 8mo ago Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebS…
CVE-2025-54290 unknown FIX debian debian 8mo ago Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wi…
CVE-2025-54293 unknown FIX debian debian 8mo ago Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on the host system via crafted log file names or symb…
CVE-2025-54291 unknown FIX debian debian 8mo ago Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code resp…
CVE-2025-61735 unknown 8mo ago Apache Kylin Server-Side Request Forgery (SSRF) Vulnerability
CVE-2025-61734 unknown 8mo ago Apache Kylin Files or Directories Accessible to External Parties
CVE-2025-61733 unknown 8mo ago Apache Kylin Authentication Bypass Vulnerability
CVE-2025-4008 unknown 1.5 KEV 8mo ago Smartbedded Meteobridge contains a command injection vulnerability that could allow remote unauthenticated attackers to gain arbitrary command execution with elevated privileges (root) on affected de…
CVE-2025-21043 unknown 1.5 KEV 8mo ago Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code.
CVE-2015-7755 unknown 2.5 KEVEXP 8mo ago Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device.
CVE-2014-6278 unknown 2.5 KEVEXPFIX debian debian 8mo ago GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment.
CVE-2025-59682 unknown FIX slesdebian debian 8mo ago An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by the "startapp --template" and "startproject --templa…
CVE-2025-59681 unknown FIX slesdebian debian 8mo ago Django vulnerable to SQL injection in column aliases
CVE-2025-43826 unknown 8mo ago Liferay Portal Vulnerable to XSS in Web Content translation
CVE-2025-43827 unknown 8mo ago Liferay Portal Vulnerable to IDOR via audit events
CVE-2025-43820 unknown 8mo ago Liferay Portal vulnerable to cross-site scripting in the Calendar widget
CVE-2025-43818 unknown 8mo ago Liferay Portal vulnerable to cross-site scripting in the Calendar widget
CVE-2025-43817 unknown 8mo ago Liferay Portal vulnerable to reflected cross-site scripting via the `redirect` parameter
CVE-2025-43815 unknown 8mo ago Liferay Portal vulnerable to reflected cross-site scripting on the page configuration page
CVE-2025-43813 unknown 8mo ago Liferay Portal vulnerable to path traversal and denial-of-service in the ComboServlet
CVE-2025-43812 unknown 8mo ago Liferay Portal vulnerable to cross-site scripting in the web content template
CVE-2025-43811 unknown 8mo ago Liferay Portal vulnerable to cross-site scripting in the related asset selector
CVE-2025-59952 unknown 8mo ago MinIO Java Client XML Tag Value Substitution Vulnerability
CVE-2025-59689 unknown 1.5 KEV 8mo ago Libraesva Email Security Gateway (ESG) contains a command injection vulnerability which allows command injection via a compressed e-mail attachment.
CVE-2025-32463 unknown 2.5 KEVEXPFIX slesdebian debian 8mo ago Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
CVE-2025-20352 unknown 1.5 KEV 8mo ago Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote code execution. A…
CVE-2025-10035 unknown 1.5 KEV 8mo ago Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, …
CVE-2025-59842 unknown debian debian 8mo ago jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to version 4.4.8, links generated with LaTeX typesetters in Markd…
CVE-2025-54831 unknown 8mo ago Apache Airflow: Connection sensitive details exposed to users with READ permissions
CVE-2025-1396 unknown 8mo ago WSO2's Input Validation Management Service contains Observable Discrepancy when Multi-Attribute Login is enabled
CVE-2025-56769 unknown 8mo ago Hutool allows remote code execution (RCE) via the QLExpressEngine class
CVE-2025-43816 unknown 8mo ago Liferay Portal and DXP vulnerable to a memory leak
CVE-2025-55560 unknown FIX debian debian 8mo ago An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor.
CVE-2025-55558 unknown FIX debian debian 8mo ago A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a…
CVE-2025-55557 unknown FIX debian debian 8mo ago A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS).
CVE-2025-55554 unknown debian debian 8mo ago pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().
CVE-2025-55553 unknown FIX debian debian 8mo ago A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).
CVE-2025-55552 unknown FIX debian debian 8mo ago pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.
CVE-2025-55551 unknown FIX debian debian 8mo ago An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.
CVE-2025-46153 unknown FIX debian debian 8mo ago PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d…
CVE-2025-46152 unknown FIX debian debian 8mo ago In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" argument.
CVE-2025-46150 unknown FIX debian debian 8mo ago In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.
CVE-2025-46149 unknown FIX debian debian 8mo ago In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.
CVE-2025-46148 unknown FIX debian debian 8mo ago In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.
CVE-2025-20362 unknown 1.5 KEV 9mo ago Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing authorization vulnerability. This vulnerability could be cha…
CVE-2025-20333 unknown 1.5 KEV 9mo ago Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution.…
CVE-2025-8869 unknown FIX slesdebian debian 9mo ago When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for th…
CVE-2025-58457 unknown FIX debian debian 9mo ago Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands
CVE-2025-48392 unknown 9mo ago Apache IoTDB: DoS Vulnerability
CVE-2025-48459 unknown 9mo ago Apache IoTDB: Deserialization of untrusted Data
CVE-2025-43819 unknown 9mo ago Liferay Portal and DXP does not properly expire sessions
CVE-2024-6429 unknown 9mo ago WSO2 Identity Server Apps allows content spoofing in logs
CVE-2025-59822 unknown 9mo ago Http4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section
CVE-2025-4760 unknown 9mo ago WSO2 carbon-apimgt affected by an authenticated stored cross-site scripting (XSS) vulnerability
CVE-2025-43814 unknown 9mo ago Liferay Portal and DXP audit events record password reminder answers
CVE-2025-43810 unknown 9mo ago Liferay Portal and DXP allows users to add a note to a different virtual instance
CVE-2025-43806 unknown 9mo ago Liferay Portal and DXP does not properly check permission with import and export tasks
CVE-2025-10585 unknown 1.5 KEVFIX debian debian 9mo ago Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-47910 unknown FIX debian debian sles 9mo ago When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than intended. CrossOriginProtection then skips validation, but forwards the original …
CVE-2025-43807 unknown 9mo ago Liferay has a stored cross-site scripting (XSS) vulnerability via a a publication’s “Name” text field
CVE-2025-6544 unknown 9mo ago H2O affected by a deserialization vulnerability
CVE-2025-40843 unknown 9mo ago CodeChecker has a buffer overflow in the log command
CVE-2025-59420 unknown FIX debian debian 9mo ago Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verification accepts tokens that declare unknown critical header parameters (crit), vi…
CVE-2025-43808 unknown 9mo ago Liferay Portal Commerce component has Incorrect Permission Assignment for Critical Resource
CVE-2025-43809 unknown 9mo ago Liferay Portal Cross-Site Request Forgery (CSRF) vulnerability
CVE-2025-43803 unknown 9mo ago Liferay Contacts Center widget has insecure direct object reference
CVE-2025-9905 unknown debian debian 9mo ago The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.
CVE-2025-9906 unknown debian debian 9mo ago Keras is vulnerable to Deserialization of Untrusted Data
CVE-2025-8419 unknown 9mo ago Keycloak SMTP Inject Vulnerability
CVE-2025-59340 unknown 9mo ago jinjava has Sandbox Bypass via JavaType-Based Deserialization
CVE-2025-59476 unknown 9mo ago Jenkins has a log message injection vulnerability
CVE-2025-59474 unknown 9mo ago Jenkins has a missing permission check, allowing users to obtain agent names
CVE-2025-43804 unknown 9mo ago Liferay search widget vulnerable to Cross-site Scripting
CVE-2025-43805 unknown 9mo ago Liferay Portal allows remote attackers to view display page templates via crafted URLs
CVE-2025-8671 unknown FIX debian debian sles 9mo ago A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource con…
CVE-2025-59432 unknown FIX debian debian sles 9mo ago Timing Attack Vulnerability in SCRAM Authentication
CVE-2025-43801 unknown 9mo ago Liferay Portal has unchecked input for loop condition vulnerability in XML-RPC
CVE-2025-10492 unknown 9mo ago JasperReports has a Java deserialisation vulnerability
CVE-2025-41243 unknown 9mo ago Spring Expression language property modification using Spring Cloud Gateway Server WebFlux
CVE-2025-41249 unknown debian debian 9mo ago Spring Framework annotation detection mechanism may result in improper authorization
CVE-2025-41248 unknown 9mo ago Spring Security annotation detection mechanism has authorization bypass
CVE-2025-59154 unknown 9mo ago Openfire has potential identity spoofing issue via unsafe CN parsing
CVE-2025-43802 unknown 9mo ago Liferay Stored Cross-site Scripting vulnerability
CVE-2025-43799 unknown 9mo ago Liferay Portal Uses Default Password
CVE-2025-43798 unknown 9mo ago Liferay DXP Missing Critical Step in Authentication
CVE-2025-43800 unknown 9mo ago Liferay Portal Cross-site Scripting (XSS) vulnerability
CVE-2025-59328 unknown 9mo ago Apache Fory Deserialization of Untrusted Data vulnerability